Privacy Policy
Last updated: 23 September 2026 · FeelGood: Dopamine Menu
Creating an account is entirely optional. Without one, FeelGood has no login and no password to remember — everything is a random identifier generated on your device, with no name, no email address, and no profile tied to a person anywhere in the system.
If you do create an account — to keep your subscription and saved routines with you on a new phone — you can sign in with Apple, Google, or an email address and password, using Firebase Authentication (operated by Google). Google Sign-In and email/password both require an email address; Sign in with Apple shares your email and name with us only if you choose to share them. Whichever you use, that address (and any name attached to it) identifies your account and nothing else — it is never sent to our analytics provider or used for marketing.
What stays on your device and never leaves
Your work-arounds (low back, knees, wrists, fatigue, pregnancy, postpartum, and pelvic floor considerations) and your body-focus check-in answers are stored only on your device, using Apple's on-device storage (SwiftData). This is true whether or not you have an account. They are never sent to us, to our analytics provider, to a language model, or synced to your account, and deleting the app deletes them. The engine that decides what to recommend runs entirely on your phone.
Calendar (optional).If you allow calendar access, FeelGood reads today's event times on your device to plan around your day. If you turn on movement recognition, it also checks event names on your device to spot workouts or classes. Calendar data stays on your device. It is never sent to our servers, to our analytics provider, or to any AI provider. You can turn access off at any time in iOS Settings.
What we collect, and why
Account sync
If you sign in, the following is synced to Cloud Firestore (also operated by Google) so it is available on your other devices:
- your kept custom routines
- a record of each completed session: its title, duration, intensity, place, and how you said you felt afterward
- your profile preferences: the activities, sports, equipment and places you chose, how often you want to move, your best time of day, the intents you picked, sessions you've hidden, your nickname and avatar, and your reminder time
Your work-arounds and check-in answers are never included in this sync. They have no path off your device, signed in or not.
Product analytics
We use PostHog to understand how the app is used — which screens are opened, whether a workout was logged or completed, whether a subscription was purchased. Each event is tied only to a random per-install identifier, never to a name or account. Signing in does not change this: analytics is never told that a sign-in happened or who it was, regardless of which method you use. Events describe what happened, not what you typed. For example, “a workout was completed” comes with the session's id, its activity type, its length, and whether it was one of your saved routines. When you complete a check-in, we record your energy level, your time budget and your place if you answered them, plus only whether you answered the body question, never the answer itself. We never send your work-arounds or your body-focus answers to analytics, and analytics never receives text you type, including routine names and chat messages. We also count how chat is used, such as whether a reply included a suggestion and whether you tapped it, without ever recording your messages.
Purchases and subscriptions
Subscription purchases are handled by Apple's App Store and processed through RevenueCat, which verifies and manages entitlement status. Before you sign in, this is tied to a random identifier RevenueCat generates. If you do sign in — with Apple, Google, or email — it is tied to your account's identifier instead, which is what lets your subscription follow you to a new phone. Neither identifier is your name or your email address.
AI-generated framing copy (Pro feature)
For paying subscribers, FeelGood can generate a short line of framing text explaining today's menu. To do this, the following — and only the following — is sent to our server, which forwards it to a language model:
- Which sessions were picked (internal ids, e.g.
app-box-breathing) - The general reason those sessions were picked (a machine-readable code, e.g. “low energy”)
- Your reported energy level and time budget for today
- How many days it's been since your last completed session (a number, never a date or the sessions themselves)
- The subscription identifier described above, so we can confirm you're a subscriber and prevent abuse
This is deliberately narrow. Your check-in's body-focus answer and your profile's work-arounds (cramping, pregnancy, postpartum, pelvic floor) are never included — there is no field for them to travel in, so this isn't a setting that can be misconfigured. If this feature is switched off or you're not a subscriber, the app makes no network requests related to it at all.
Chat (Pro feature)
For paying subscribers, FeelGood includes a chat. When you send a message, it goes to our server and then to an AI model provider (Google Gemini) to write a reply. Our server is hosted by Cloudflare, which also processes your message to look up help content. Chat messages are processed by the AI provider, so please don't type sensitive personal or health details into chat. If you mention your body or health in a message, what you type is sent as described here. What is sent:
- The message you type, after we scrub out email addresses, phone numbers, links, and some health-related words (scrubbing is automatic and not perfect)
- Your recent chat history, so replies make sense in context
- Today's menu: the titles, lengths, and short reasons for the sessions on it, including the names of routines you created if they are on it
- A small amount of context: activities you've liked, how you last said you felt, your recent completed-session count, sessions you've hidden, and your preferred intensity and fatigue sensitivity
- The subscription identifier described above, so we can confirm you're a subscriber and prevent abuse
Our server does not store your chat messages or the replies. Basic technical logs, such as error messages and timings, are kept for a few days and do not include what you typed. If you don't use chat, or you turn off “AI replies in Chat” in My account, none of this is sent. Chat then works entirely on your phone.
Push notifications and in-app messages
We use OneSignal to send notifications and in-app messages. It receives a push token and device information and, if you're signed in, your account ID (a random identifier, not your name or email), plus which sessions you start, pause, resume, finish, or discard, each with a session ID and start time, so notifications can follow your account rather than one device. You can turn notifications off at any time in iOS Settings.
Crash and error reports
If the app crashes or hits an error, technical details (device model, iOS version, and the error) are sent to PostHog to help us fix it.
Embedded video
Some sessions are Pilates and wellness classes embedded from YouTube's official player. Watching one of these is subject to YouTube's own Privacy Policy and Terms of Service, which are Google's, not ours.
What we don't do
- No advertising SDKs, no ad tracking
- No cross-app or cross-website tracking of any kind (nothing to request App Tracking Transparency consent for)
- We never sell personal data or share it with third parties for their own marketing
- We never send your account email, your routine names, or your work-arounds to our analytics provider
- Our notification provider (OneSignal) receives your account ID, push token, device information, and session activity as described above — never your email address or your check-in answers
Your choices
If you created an account, you can delete it at any time in the app: tap the gear icon, then My account, then “Delete account”. When you do, we delete your account and the routines, workout history, and profile preferences synced to it. Deletion starts when you confirm, and copies held in backups are removed on a routine schedule. Records held by our service providers under your account ID, such as your purchase record with RevenueCat and your notification profile with OneSignal, are not deleted automatically. Email us below and we will have them removed. If you signed in with Apple, you can also revoke this app's access in iOS Settings under your Apple Account. Deleting the app removes everything stored on your device, account or not. If you never created an account, we hold no name, email or account to delete. Analytics records exist only under a random identifier, and we can only act on those if you send us that identifier.
How long we keep data
- Chat messages and replies: not stored on our server. Server logs (timings and errors, never the content of your messages): about 3 days
- Account data (synced routines, session history, and profile preferences): until you delete your account; deletion starts when you confirm, and copies held in backups are removed on a routine schedule
- Analytics and crash reports (PostHog): kept for up to 1 year under a random per-install identifier, then deleted
To ask us to delete data held under a random identifier, or for any other privacy request, email us at the address below.
Children
FeelGood is not directed at children under 13 and we do not knowingly collect data from them.
Changes to this policy
If this policy changes, the update will be posted on this page with a new “Last updated” date.